Privacy Policy
Last updated: 2026-07-15 Version: 1.1
1. Data controller
TakeMe, a SASU with share capital of €15,000, registered office at 229 rue de Solférino, 59800 Lille, France (SIREN 993 936 350), represented by its president Valentin Drygas.
Contact: privacy@take-me.fr
2. Data collected
2.1 Data provided directly by the user
- Identity: email, password (hashed), first name, last name, date of birth
- Freelance profile: photo, bio, profession, portfolio, indicative rates, service area (geolocation)
- Client profile: first name, city
- Communications: messages exchanged with other users, reports
- Missions: title, description, budget, dates, reviews given/received
2.2 Data collected automatically
- Technical logs: IP address (anonymised), browser, OS
- Analytics cookies (with explicit consent only): pages visited, session duration
2.3 Google Calendar data (optional connection)
If a freelancer chooses to connect their Google Calendar account from the Settings page (an optional feature), TakeMe accesses, read-only, the busy time ranges of their primary calendar, via the Google Calendar freeBusy API and the https://www.googleapis.com/auth/calendar.readonly scope. TakeMe never accesses event titles, descriptions, attendees, or any other event content — only "busy / free" time intervals. This processing is detailed in section 7.
3. Purposes
| Purpose | GDPR legal basis |
|---|---|
| Account creation and management | Performance of the contract (art. 6.1.b) |
| Client/freelance matching | Performance of the contract |
| Moderation and security | Legitimate interest (art. 6.1.f) |
| Analytics and product improvement | Consent (art. 6.1.a) |
| Transactional communications (mission emails) | Performance of the contract |
| Availability synchronisation (Google Calendar) | Consent (art. 6.1.a) |
| Legal obligations | Legal obligation (art. 6.1.c) |
4. Retention period
- Account data: duration of the contractual relationship + 3 years after deletion
- Login logs: 12 months
- Mission data: 5 years (accounting obligations)
- Analytics cookies: 13 months max (CNIL)
- Google Calendar busy ranges: transient retention (rolling 8-week window), refreshed on each synchronisation and deleted when the calendar is disconnected
5. Recipients
- TakeMe team (limited access)
- Supabase (hosting, EU — Germany)
- Resend (transactional email, EU)
- Sentry (error monitoring, EU)
- PostHog (analytics, EU — with consent)
- Mapbox (mapping, USA — minimised data: coordinates only)
- Mistral AI (search-text interpretation, EU — see section 8)
- OpenAI (fallback for search-text interpretation, USA — see section 8)
Google Calendar data (section 2.3) is shared with none of these recipients, nor with any other third party (see section 7).
6. Transfers outside the EU
- Mapbox is hosted in the United States. The only data transmitted is the geographic coordinates needed to render the map. Contractual safeguards: Mapbox Standard Contractual Clauses (SCC).
- OpenAI (used only as a fallback for Mistral) is hosted in the United States. The only data transmitted is the user's search text (see section 8). Contractual safeguards: Standard Contractual Clauses (SCC).
No Google Calendar data is transferred outside the EU (nor, within the EU, to any third party): it is stored only with Supabase (EU).
7. Google Workspace API data (Google Calendar): access, sharing & Limited Use
- Data concerned: only the "busy" time ranges of the freelancer's primary calendar, obtained via the Google Calendar
freeBusyAPI with thehttps://www.googleapis.com/auth/calendar.readonlyscope (read-only). No event content (title, description, guests, location) is read or stored. - Sole purpose: to mark the corresponding time slots as unavailable in the freelancer's availability, in order to prevent double bookings.
- With whom this data is shared, transferred, or disclosed: with no one outside TakeMe. It is stored only in our Supabase database (hosted in the EU) and is never transmitted to any third party — not to Mapbox, PostHog, Resend, Sentry, Mistral, OpenAI, or any other service or artificial-intelligence service.
- No AI/ML training: this data is never used, transferred, or sold to create, train, or improve artificial-intelligence or machine-learning models, whether generalised or specialised.
- Revocation: the freelancer can disconnect their calendar at any time from the Settings page; the corresponding busy ranges are then deleted.
- Limited Use statement: TakeMe's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
8. Artificial-intelligence (AI/ML) processing
TakeMe uses AI models for a single purpose: to interpret the free-text search entered by a client (and requests for new professions) in order to extract the profession, city, and budget being sought.
- Providers: Mistral AI (
mistral-small-latest, hosted in the EU) as primary; OpenAI (gpt-4o-mini) as a fallback when Mistral is unavailable. Access is via their paid commercial ("pay-as-you-go") APIs. - Data transmitted: only the search text or profession request entered by the user. No Google Calendar data, no calendar data, and no Google Workspace content is ever transmitted to these services.
- No training: in accordance with the API terms of Mistral and OpenAI, data sent via their API is not used to train their models.
9. Your GDPR rights
You have the following rights:
- Access: know what data is processed (JSON export available in /settings)
- Rectification: edit your data via your profile
- Erasure: delete your account (30-day grace period, then hard-delete)
- Portability: JSON export available in /settings
- Objection: refuse analytics cookies (consent banner)
- Restriction: on request to privacy@take-me.fr
- Withdraw consent: at any time via /settings (including disconnecting Google Calendar)
To exercise these rights: privacy@take-me.fr. Response within 1 month.
Complaints: your national data protection authority (in France: CNIL — https://www.cnil.fr/en/plaintes).
10. Security
- Hashed passwords (bcrypt)
- HTTPS enforced
- Postgres RLS (Row-Level Security) on all tables
- 2FA for administrators
11. Minors
Registration is reserved for adults (18+). Any account belonging to a minor will be deleted upon report.
12. Cookies
Categories:
- Necessary: auth session (always active)
- Analytics: PostHog (opt-in)
13. Changes
This policy may evolve. Email notification for substantial changes.